Malicious Package Affecting @withgoogle/stitch-sdk package, versions *


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-WITHGOOGLESTITCHSDK-17391452
  • published21 Jun 2026
  • disclosed20 Jun 2026
  • creditSafeDep Team

Introduced: 20 Jun 2026

Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the @withgoogle/stitch-sdk package.

Overview

@withgoogle/stitch-sdk is a malicious package. Although this package attempts to impersonate Google's Stitch AI design tool, there is no connection between Google and this package. By squatting the @withgoogle npm scope, a malicious actor published @withgoogle/stitch-sdk in an attempt to mimic the legitimate @google/stitch-sdk package. The attacker included deliberately misleading text in the package's README and CLI help menu, falsely positioning this package as the legitimate "new version" of the SDK.

Malicious Behavior

According to the analysis, the payload establishes execution via a preinstall hook and a CLI binary. Once executed, it silently harvests developer credentials, explicitly prioritizing access to AI coding tools such as Claude Code. It then sweeps for credentials across git config, SSH public keys, GitHub CLI, npm configurations, and Docker configurations. The stolen data is then exfiltrated to an attacker-controlled server via HTTPS GET requests.

Notes:

  1. The attacker mimicked version numbers (v0.1.1 and v0.1.2) of the legitimate package to further reinforce the impersonation.
  2. The credential exfiltration disables TLS certificate validation to ensure outbound requests complete successfully.
  3. If you installed this package, you have been compromised and should immediately rotate credentials for any affected tools (git, GitHub, npm, Docker, Claude Code, etc.).

References

CVSS Base Scores

version 4.0
version 3.1